Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: how to get rid antivirus 2009  (Read 26392 times)

0 Members and 1 Guest are viewing this topic.

delgado

    Topic Starter


    Beginner

    how to get rid antivirus 2009
    « on: September 20, 2008, 09:15:35 PM »
    have an acer computer,windows vista how can i get rid of antivirus 2009 virus?

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: how to get rid antivirus 2009
    « Reply #1 on: September 20, 2008, 10:13:47 PM »
    Welcome to CH.

    Start here http://www.computerhope.com/forum/index.php?topic=46313.0

    Post the 3 logs when complete.

    delgado

      Topic Starter


      Beginner

      Re: how to get rid antivirus 2009
      « Reply #2 on: September 20, 2008, 10:28:26 PM »
      ok thanks,i will have to do this tomorrow its my daughters computer thats infected 'preciate the help

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: how to get rid antivirus 2009
      « Reply #3 on: September 20, 2008, 11:08:11 PM »
      The forums will be down for a server change tomorrow. I'm not sure how long so don't think we have disappeared if you can't get here for a while Maybe most of the day or maybe not depending how smooth it goes.

      delgado

        Topic Starter


        Beginner

        Re: how to get rid antivirus 2009
        « Reply #4 on: September 20, 2008, 11:48:30 PM »
        ok thanks once again

        delgado

          Topic Starter


          Beginner

          Re: how to get rid antivirus 2009
          « Reply #5 on: September 21, 2008, 01:06:32 PM »
          SUPERAntiSpyware Scan Log
          http://www.superantispyware.com

          Generated 09/21/2008 at 10:57 AM

          Application Version : 4.21.1004

          Core Rules Database Version : 3575
          Trace Rules Database Version: 1563

          Scan type       : Complete Scan
          Total Scan Time : 00:40:12

          Memory items scanned      : 394
          Memory threats detected   : 1
          Registry items scanned    : 5342
          Registry threats detected : 92
          File items scanned        : 19509
          File threats detected     : 35

          Adware.MyWebSearch
             C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOEMON.EXE
             C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOEMON.EXE
             [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
             C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
             [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
             HKLM\Software\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
             HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}
             HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}
             HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\InprocServer32
             HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
             HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\Programmable
             C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\1.BIN\MWSSRCAS.DLL
             HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
             HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
             HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
             HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32
             HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
             HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\Programmable
             HKLM\Software\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
             HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
             HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
             HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32
             HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
             C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
             HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
             HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
             HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
             HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32
             HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
             HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}
             HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
             HKLM\Software\Microsoft\Internet Explorer\Toolbar#{07B18EA9-A523-4961-B6BB-170DE4475CCA}
             HKU\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks#{00A6FAF6-072E-44cf-8957-5838F569A31D}
             HKU\S-1-5-21-2367156795-2628951264-1224408995-1000\Software\Microsoft\Internet Explorer\URLSearchHooks#{00A6FAF6-072E-44cf-8957-5838F569A31D}
             HKU\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks#{00A6FAF6-072E-44cf-8957-5838F569A31D}

          Trojan.Dropper/Gen
             [cageaew] C:\USERS\LOGAN\APPDATA\LOCAL\CAGEAEW.EXE
             C:\USERS\LOGAN\APPDATA\LOCAL\CAGEAEW.EXE
             C:\USERS\LOGAN\APPDATA\LOCAL\IDXUSJFKAM.EXE
             C:\USERS\LOGAN\APPDATA\LOCAL\YUEIACQ.EXE

          Trojan.Media-Codec
             C:\Program Files\PCHealthCenter\0.gif
             C:\Program Files\PCHealthCenter\2.gif
             C:\Program Files\PCHealthCenter\3.gif
             C:\Program Files\PCHealthCenter\5.exe
             C:\Program Files\PCHealthCenter\sc.html
             C:\Program Files\PCHealthCenter\sex1.ico
             C:\Program Files\PCHealthCenter\sex2.ico
             C:\Program Files\PCHealthCenter

          Adware.180solutions/Seekmo
             HKCR\HostIE.Bho
             HKCR\HostIE.Bho\CLSID
             HKCR\HostIE.Bho\CurVer
             HKCR\HostIE.Bho.1
             HKCR\HostIE.Bho.1\CLSID

          Adware.Zango Toolbar/Hb
             HKCR\CoreSrv.CoreServices
             HKCR\CoreSrv.CoreServices\CLSID
             HKCR\CoreSrv.CoreServices\CurVer
             HKCR\CoreSrv.CoreServices.1
             HKCR\CoreSrv.CoreServices.1\CLSID
             HKCR\CoreSrv.LfgAx
             HKCR\CoreSrv.LfgAx\CLSID
             HKCR\CoreSrv.LfgAx\CurVer
             HKCR\CoreSrv.LfgAx.1
             HKCR\CoreSrv.LfgAx.1\CLSID
             HKCR\HBMain.CommBand
             HKCR\HBMain.CommBand\CLSID
             HKCR\HBMain.CommBand\CurVer
             HKCR\HBMain.CommBand.1
             HKCR\HBMain.CommBand.1\CLSID
             HKCR\hbr.HbMain
             HKCR\hbr.HbMain\CLSID
             HKCR\hbr.HbMain\CurVer
             HKCR\hbr.HbMain.1
             HKCR\hbr.HbMain.1\CLSID
             HKCR\HostOL.MailAnim
             HKCR\HostOL.MailAnim\CLSID
             HKCR\HostOL.MailAnim\CurVer
             HKCR\HostOL.MailAnim.1
             HKCR\HostOL.MailAnim.1\CLSID
             HKCR\HostOL.WebmailSend
             HKCR\HostOL.WebmailSend\CLSID
             HKCR\HostOL.WebmailSend\CurVer
             HKCR\HostOL.WebmailSend.1
             HKCR\HostOL.WebmailSend.1\CLSID
             HKCR\InstIE.HbInstObj
             HKCR\InstIE.HbInstObj\CLSID
             HKCR\InstIE.HbInstObj\CurVer
             HKCR\InstIE.HbInstObj.1
             HKCR\InstIE.HbInstObj.1\CLSID
             HKCR\Srv.CoreServices
             HKCR\Srv.CoreServices\CLSID
             HKCR\Srv.CoreServices\CurVer
             HKCR\Srv.CoreServices.1
             HKCR\Srv.CoreServices.1\CLSID
             HKCR\Toolbar.HtmlMenuUI
             HKCR\Toolbar.HtmlMenuUI\CLSID
             HKCR\Toolbar.HtmlMenuUI\CurVer
             HKCR\Toolbar.HtmlMenuUI.1
             HKCR\Toolbar.HtmlMenuUI.1\CLSID
             HKCR\Toolbar.ToolbarCtl
             HKCR\Toolbar.ToolbarCtl\CLSID
             HKCR\Toolbar.ToolbarCtl\CurVer
             HKCR\Toolbar.ToolbarCtl.1
             HKCR\Toolbar.ToolbarCtl.1\CLSID

          Adware.Zango/ShoppingReport
             HKCR\WeatherDPA.WeatherController
             HKCR\WeatherDPA.WeatherController\CLSID
             HKCR\WeatherDPA.WeatherController\CurVer
             HKCR\WeatherDPA.WeatherController.1
             HKCR\WeatherDPA.WeatherController.1\CLSID
             C:\Users\logan\AppData\Roaming\WeatherDPA\Weather\log.txt
             C:\Users\logan\AppData\Roaming\WeatherDPA\Weather\WeatherDPA\Weather_XML
             C:\Users\logan\AppData\Roaming\WeatherDPA\Weather\WeatherDPA
             C:\Users\logan\AppData\Roaming\WeatherDPA\Weather\WeatherStartup.xml
             C:\Users\logan\AppData\Roaming\WeatherDPA\Weather
             C:\Users\logan\AppData\Roaming\WeatherDPA

          Rogue.AntiSpywareExpert
             HKU\S-1-5-21-2367156795-2628951264-1224408995-1000\Software\AntiSpywareExpert
             C:\Program Files\AntiSpywareExpert
             C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiSpywareExpert\AntiSpywareExpert.lnk
             C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiSpywareExpert\Uninstall AntiSpywareExpert.lnk
             C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiSpywareExpert
             C:\Users\logan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AntiSpywareExpert.lnk
             C:\Users\logan\Desktop\AntiSpywareExpert.lnk

          Rogue.UltimateAntiVirus
             C:\Program Files\VAV\vav.ooo
             C:\Program Files\VAV\vav0.dat
             C:\Program Files\VAV\vav1.dat
             C:\Program Files\VAV

          Rogue.AntiVirus 2009
             C:\Program Files\Antivirus 2009
             C:\Users\logan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk

          Adware.Tracking Cookie
             C:\Users\logan\AppData\Roaming\Microsoft\Windows\Cookies\Low\logan@revsci[2].txt

          Trojan.Unknown Origin
             C:\WINDOWS\SYSTEM32\SEX1.ICO

          delgado

            Topic Starter


            Beginner

            Re: how to get rid antivirus 2009
            « Reply #6 on: September 21, 2008, 01:38:09 PM »
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 12:36:44 PM, on 9/21/2008
            Platform: Windows Vista  (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16711)
            Boot mode: Safe mode with network support

            Running processes:
            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\svchost.exe
            C:\Program Files\Spyware Doctor\pctsAuxs.exe
            C:\Program Files\Spyware Doctor\pctsSvc.exe
            C:\Program Files\Spyware Doctor\pctsTray.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
            O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
            O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
            O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
            O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
            O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
            O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
            O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
            O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
            O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
            O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
            O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
            O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe
            O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
            O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
            O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
            O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
            O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
            O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
            O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
            O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
            O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
            O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
            O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
            O4 - Global Startup: Empowering Technology Launcher.lnk = ?
            O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\logan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
            O13 - Gopher Prefix:
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
            O20 - AppInit_DLLs: eNetHook.dll,avgrsstx.dll
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
            O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
            O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
            O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
            O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
            O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
            O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
            O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
            O23 - Service: Fix-It Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
            O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
            O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
            O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
            O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

            --
            End of file - 9815 bytes

            delgado

              Topic Starter


              Beginner

              Re: how to get rid antivirus 2009
              « Reply #7 on: September 21, 2008, 01:57:23 PM »
              Malwarebytes' Anti-Malware 1.28
              Database version: 1186
              Windows 6.0.6000

              9/21/2008 12:48:46 PM
              mbam-log-2008-09-21 (12-48-46).txt

              Scan type: Quick Scan
              Objects scanned: 36358
              Time elapsed: 2 minute(s), 21 second(s)

              Memory Processes Infected: 0
              Memory Modules Infected: 1
              Registry Keys Infected: 133
              Registry Values Infected: 15
              Registry Data Items Infected: 0
              Folders Infected: 17
              Files Infected: 69

              Memory Processes Infected:
              (No malicious items detected)

              Memory Modules Infected:
              C:\Program Files\Internet Explorer\msimg32.dll (Adware.MyWebSearch) -> Delete on reboot.

              Registry Keys Infected:
              HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\TypeLib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\TypeLib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\TypeLib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\TypeLib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\TypeLib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\TypeLib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\TypeLib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\TypeLib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\TypeLib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mywebsearchservice (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\mywebsearchservice (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\mywebsearchservice (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mywebsearchservice (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

              delgado

                Topic Starter


                Beginner

                Re: how to get rid antivirus 2009
                « Reply #8 on: September 21, 2008, 01:59:08 PM »
                Registry Values Infected:
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\my web search bar search scope monitor (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue73ba.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue7cbf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue81dd.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue85d3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue978f.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue73ba.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue7cbf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue81dd.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue85d3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sue978f.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                Registry Data Items Infected:
                (No malicious items detected)

                Folders Infected:
                C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\SrchAstt\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.

                Files Infected:
                C:\Users\logan\Local Settings\Application Data\cageaew_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                C:\Users\logan\Local Settings\Application Data\cageaew_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                C:\Users\logan\Local Settings\Application Data\cageaew.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                C:\Program Files\Internet Explorer\msimg32.dll (Adware.MyWebSearch) -> Delete on reboot.
                C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Windows\System32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Website.lnk (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65\ProfileReg.dat (Adware.Seekmo) -> Quarantined and deleted successfully.
                C:\Windows\System32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
                sorry but i did not remove on maleware scan,heres the new scan

                delgado

                  Topic Starter


                  Beginner

                  Re: how to get rid antivirus 2009
                  « Reply #9 on: September 21, 2008, 02:02:56 PM »
                  ok heres my logs sorry theyre not in correct order ,but had trouble posting and forgot to remove all on maleware scan if you can help it would be greatly appreciated ,thanks

                  delgado

                    Topic Starter


                    Beginner

                    Re: how to get rid antivirus 2009
                    « Reply #10 on: September 21, 2008, 06:13:23 PM »
                    Malwarebytes' Anti-Malware 1.28
                    Database version: 1186
                    Windows 6.0.6000

                    9/21/2008 5:11:04 PM
                    mbam-log-2008-09-21 (17-11-04).txt

                    Scan type: Quick Scan
                    Objects scanned: 39288
                    Time elapsed: 6 minute(s), 53 second(s)

                    Memory Processes Infected: 0
                    Memory Modules Infected: 0
                    Registry Keys Infected: 0
                    Registry Values Infected: 0
                    Registry Data Items Infected: 0
                    Folders Infected: 0
                    Files Infected: 0

                    Memory Processes Infected:
                    (No malicious items detected)

                    Memory Modules Infected:
                    (No malicious items detected)

                    Registry Keys Infected:
                    (No malicious items detected)

                    Registry Values Infected:
                    (No malicious items detected)

                    Registry Data Items Infected:
                    (No malicious items detected)

                    Folders Infected:
                    (No malicious items detected)

                    Files Infected:
                    (No malicious items detected)
                    this is a second maleware scan in norml mode had to scan first time in safe mode ie would not pull up after reboot

                    evilfantasy

                    • Malware Removal Specialist
                    • Moderator


                    • Genius
                    • Calm like a bomb
                    • Thanked: 493
                    • Experience: Experienced
                    • OS: Windows 11
                    Re: how to get rid antivirus 2009
                    « Reply #11 on: September 21, 2008, 11:50:33 PM »
                    Download DrWeb CureIt & save it to your desktop.

                    Scan with DrWeb-CureIt as follows:
                    • Double-click on drweb-cureit.exe and then click Start.
                    • An Express Scan of your PC notice will appear.
                    • Under Start the Express Scan Now Click OK to start.
                      • This is a short scan that will scan the files currently running in memory.
                      • If or when something is found, click the Yes button when it asks you if you want to cure it.
                    • Once the short scan has finished, Click Options > Change settings
                    • Choose the Scan tab and UNcheck Heuristic analysis and click OK
                    • Back at the main window, select the Complete scan button.
                    • Then click the Green Arrow Start Scanning button on the right and the scan will start.
                      • Click Yes to all if it asks if you want to cure/move any file(s).
                    • When the scan is done.
                    • In the Dr.Web CureIt menu on top left, click File and choose Save report list.
                    • Save the DrWeb.csv report to your Desktop.
                    • Exit Dr.Web Cureit.
                    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
                    [/COLOR]
                    • After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
                    • Copy and paste that log in the next reply
                    .
                    ----------

                    Now run a new HijackThis scan and post that log also.

                    delgado

                      Topic Starter


                      Beginner

                      Re: how to get rid antivirus 2009
                      « Reply #12 on: September 22, 2008, 01:26:37 PM »
                      data001\data003;C:\Program Files\Morpheus\morpheustoolbar.exe\data001;Adware.Msearch;;
                      data001\data006;C:\Program Files\Morpheus\morpheustoolbar.exe\data001;Adware.Msearch;;
                      data001;C:\Program Files\Morpheus\morpheustoolbar.exe;Archive contains infected objects;;
                      morpheustoolbar.exe;C:\Program Files\Morpheus;Archive contains infected objects;Moved.;
                      dr web log.

                      delgado

                        Topic Starter


                        Beginner

                        Re: how to get rid antivirus 2009
                        « Reply #13 on: September 22, 2008, 01:27:48 PM »
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Spyware Doctor\pctsAuxs.exe
                        C:\Program Files\Spyware Doctor\pctsSvc.exe
                        C:\Program Files\Spyware Doctor\pctsTray.exe
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                        C:\Windows\system32\wbem\wmiprvse.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
                        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                        O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                        O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                        O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                        O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
                        O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
                        O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                        O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                        O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
                        O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
                        O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe
                        O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                        O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                        O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                        O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                        O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                        O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
                        O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                        O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                        O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                        O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                        O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                        O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                        O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                        O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\logan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
                        O13 - Gopher Prefix:
                        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                        O20 - AppInit_DLLs: eNetHook.dll,avgrsstx.dll
                        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                        O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                        O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                        O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                        O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                        O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                        O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                        O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                        O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                        O23 - Service: Fix-It Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                        O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
                        O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                        O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
                        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                        O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                        --
                        End of file - 9815 bytes

                        evilfantasy

                        • Malware Removal Specialist
                        • Moderator


                        • Genius
                        • Calm like a bomb
                        • Thanked: 493
                        • Experience: Experienced
                        • OS: Windows 11
                        Re: how to get rid antivirus 2009
                        « Reply #14 on: September 22, 2008, 07:49:01 PM »
                        Please update MalwareBytes and run a new scan then post the log.

                        Also once that is complete run a new HijackThis scan and post that log also.

                        zuratai



                          Intermediate

                          Re: how to get rid antivirus 2009
                          « Reply #15 on: September 22, 2008, 10:09:58 PM »
                          hmm i got this b4 and all i ran was The malwarebytes  removed it right away

                          delgado

                            Topic Starter


                            Beginner

                            Re: how to get rid antivirus 2009
                            « Reply #16 on: September 23, 2008, 09:04:48 AM »
                            Malwarebytes' Anti-Malware 1.28
                            Database version: 1199
                            Windows 6.0.6000

                            9/23/2008 11:03:53 AM
                            mbam-log-2008-09-23 (11-03-53).txt

                            Scan type: Quick Scan
                            Objects scanned: 39335
                            Time elapsed: 5 minute(s), 26 second(s)

                            Memory Processes Infected: 0
                            Memory Modules Infected: 0
                            Registry Keys Infected: 0
                            Registry Values Infected: 0
                            Registry Data Items Infected: 0
                            Folders Infected: 0
                            Files Infected: 0

                            Memory Processes Infected:
                            (No malicious items detected)

                            Memory Modules Infected:
                            (No malicious items detected)

                            Registry Keys Infected:
                            (No malicious items detected)

                            Registry Values Infected:
                            (No malicious items detected)

                            Registry Data Items Infected:
                            (No malicious items detected)

                            Folders Infected:
                            (No malicious items detected)

                            Files Infected:
                            (No malicious items detected)

                            delgado

                              Topic Starter


                              Beginner

                              Re: how to get rid antivirus 2009
                              « Reply #17 on: September 23, 2008, 09:11:00 AM »
                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 12:36:44 PM, on 9/21/2008
                              Platform: Windows Vista  (WinNT 6.00.1904)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                              Boot mode: Safe mode with network support

                              Running processes:
                              C:\Windows\System32\smss.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\wininit.exe
                              C:\Windows\system32\winlogon.exe
                              C:\Windows\system32\services.exe
                              C:\Windows\system32\lsass.exe
                              C:\Windows\system32\lsm.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\Explorer.EXE
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\Spyware Doctor\pctsAuxs.exe
                              C:\Program Files\Spyware Doctor\pctsSvc.exe
                              C:\Program Files\Spyware Doctor\pctsTray.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                              C:\Windows\system32\wbem\wmiprvse.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
                              O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                              O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                              O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                              O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                              O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                              O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
                              O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
                              O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                              O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                              O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
                              O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
                              O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe
                              O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                              O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                              O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                              O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                              O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                              O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
                              O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                              O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                              O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                              O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                              O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                              O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                              O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                              O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\logan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
                              O13 - Gopher Prefix:
                              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                              O20 - AppInit_DLLs: eNetHook.dll,avgrsstx.dll
                              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                              O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                              O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                              O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                              O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                              O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                              O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                              O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                              O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                              O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                              O23 - Service: Fix-It Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                              O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
                              O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                              O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
                              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                              O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                              --
                              End of file - 9815 bytes

                              evilfantasy

                              • Malware Removal Specialist
                              • Moderator


                              • Genius
                              • Calm like a bomb
                              • Thanked: 493
                              • Experience: Experienced
                              • OS: Windows 11
                              Re: how to get rid antivirus 2009
                              « Reply #18 on: September 23, 2008, 10:02:41 AM »
                              Do you use either of these?

                              MyWebSearch Plugin
                              My Web Search Bar Search Scope Monitor


                              The HijackThis log is an old one. Please run a new scan from Normal boot mode and post the log.

                              delgado

                                Topic Starter


                                Beginner

                                Re: how to get rid antivirus 2009
                                « Reply #19 on: September 23, 2008, 01:20:38 PM »
                                i dont use my web but my daughter might be ,started this new hjt scan and it came up saying for some reason your system denied write access to the hosts  file ,here is the log                           Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 12:36:44 PM, on 9/21/2008
                                Platform: Windows Vista  (WinNT 6.00.1904)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                                Boot mode: Safe mode with network support

                                Running processes:
                                C:\Windows\System32\smss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                C:\Program Files\Spyware Doctor\pctsSvc.exe
                                C:\Program Files\Spyware Doctor\pctsTray.exe
                                C:\Program Files\Windows Media Player\wmpnscfg.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                C:\Windows\system32\wbem\wmiprvse.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
                                O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                                O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
                                O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
                                O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
                                O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
                                O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe
                                O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                                O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
                                O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                                O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\logan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
                                O13 - Gopher Prefix:
                                O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                O20 - AppInit_DLLs: eNetHook.dll,avgrsstx.dll
                                O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                                O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                                O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                                O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                                O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                                O23 - Service: Fix-It Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
                                O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                                O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
                                O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                                O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                                O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                --
                                End of file - 9815 bytes
                                                                 

                                evilfantasy

                                • Malware Removal Specialist
                                • Moderator


                                • Genius
                                • Calm like a bomb
                                • Thanked: 493
                                • Experience: Experienced
                                • OS: Windows 11
                                Re: how to get rid antivirus 2009
                                « Reply #20 on: September 23, 2008, 01:24:03 PM »
                                Can you get a HiajckThis log from Normal boot mode?

                                delgado

                                  Topic Starter


                                  Beginner

                                  Re: how to get rid antivirus 2009
                                  « Reply #21 on: September 23, 2008, 01:43:48 PM »
                                  no i can not ,restarted computer windows normally and this is the log from new scan dont Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 12:36:44 PM, on 9/21/2008
                                  Platform: Windows Vista  (WinNT 6.00.1904)
                                  MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                                  Boot mode: Safe mode with network support

                                  Running processes:
                                  C:\Windows\System32\smss.exe
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\wininit.exe
                                  C:\Windows\system32\winlogon.exe
                                  C:\Windows\system32\services.exe
                                  C:\Windows\system32\lsass.exe
                                  C:\Windows\system32\lsm.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                  C:\Program Files\Spyware Doctor\pctsSvc.exe
                                  C:\Program Files\Spyware Doctor\pctsTray.exe
                                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                  C:\Windows\system32\wbem\wmiprvse.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
                                  O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                  O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                  O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                  O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                  O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                  O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
                                  O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
                                  O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                  O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
                                  O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
                                  O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe
                                  O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                                  O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                  O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                  O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                  O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                  O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                  O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
                                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                  O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
                                  O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                  O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                  O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                  O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                  O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                  O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                                  O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\logan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
                                  O13 - Gopher Prefix:
                                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                  O20 - AppInit_DLLs: eNetHook.dll,avgrsstx.dll
                                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                  O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                                  O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                  O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                  O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                  O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                                  O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                                  O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                                  O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                  O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                                  O23 - Service: Fix-It Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                  O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
                                  O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                                  O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
                                  O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                  O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                                  O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                  --
                                  End of file - 9815 bytes
                                  understand             

                                  delgado

                                    Topic Starter


                                    Beginner

                                    Re: how to get rid antivirus 2009
                                    « Reply #22 on: September 23, 2008, 01:53:46 PM »
                                    man, tried again same thing wonder why windows wont start normally?

                                    delgado

                                      Topic Starter


                                      Beginner

                                      Re: how to get rid antivirus 2009
                                      « Reply #23 on: September 23, 2008, 02:25:14 PM »
                                      computer is stuck in safe mode for some reason

                                      evilfantasy

                                      • Malware Removal Specialist
                                      • Moderator


                                      • Genius
                                      • Calm like a bomb
                                      • Thanked: 493
                                      • Experience: Experienced
                                      • OS: Windows 11
                                      Re: how to get rid antivirus 2009
                                      « Reply #24 on: September 23, 2008, 05:05:14 PM »
                                      Open HijackThis and select Do a system scan only.

                                      Place a check mark next to the following entries: (if there)

                                      - O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                      - O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                      - O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                      - O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                      - O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                      - O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
                                      - O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                      - O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                      - O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                      - O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                      - O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe


                                      Important: Close all windows except for HijackThis and then click Fix checked.

                                      Exit HijackThis.

                                      ----------

                                      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

                                      Go to Start > Run and type notepad.exe then click OK

                                      Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

                                      Code: [Select]
                                      REGEDIT4

                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
                                      "\SUE73BA.exe"=-
                                      "\SUE7CBF.exe"=-
                                      "\SUE81DD.exe"=-
                                      "\SUE85D3.exe"=-
                                      "\SUE978F.exe"=-

                                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
                                      "\SUE73BA.exe"=-
                                      "\SUE7CBF.exe"=-
                                      "\SUE81DD.exe"=-
                                      "\SUE85D3.exe"=-
                                      "\SUE978F.exe"=-

                                      Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

                                      ----------

                                      Create An Uninstall List
                                      • Start HijackThis
                                      • Click on the Open the Misc Tools section
                                      • Click on the Open Uninstall Manager button.
                                      • Click on the Save list button and specify where you would like to save this file and click Save.
                                        • When you press Save button a notepad will open with the contents of that file.
                                      • Copy and paste that list in your reply.

                                      delgado

                                        Topic Starter


                                        Beginner

                                        Re: how to get rid antivirus 2009
                                        « Reply #25 on: September 23, 2008, 08:40:39 PM »
                                        Acer Assist
                                        Acer eDataSecurity Management
                                        Acer eLock Management
                                        Acer Empowering Technology
                                        Acer eNet Management
                                        Acer ePower Management
                                        Acer ePresentation Management
                                        Acer eSettings Management
                                        Acer GridVista
                                        Acer Mobility Center Plug-In
                                        Acer Registration
                                        Acer ScreenSaver
                                        Acer Tour
                                        Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
                                        Adobe Flash Player ActiveX
                                        Adobe Reader 8.1.2
                                        Adobe Shockwave Player
                                        Agere Systems HDA Modem
                                        ALPS Touch Pad Driver
                                        Apple Mobile Device Support
                                        Apple Software Update
                                        AVG Free 8.0
                                        Burn4Free CD and DVD
                                        CCleaner (remove only)
                                        Drivers Install For Linksys Easylink Advisor
                                        Favorit
                                        Fix-It Utilities 8 Professional
                                        FrostWire 4.13.5
                                        Google Toolbar for Internet Explorer
                                        Google Toolbar for Internet Explorer
                                        GTOneCare
                                        HijackThis 2.0.2
                                        Intel(R) Graphics Media Accelerator Driver
                                        Java(TM) 6 Update 7
                                        Launch Manager
                                        Linksys EasyLink Advisor 1.6 (0032)
                                        Malwarebytes' Anti-Malware
                                        Microsoft Visual C++ 2005 Redistributable
                                        MSXML 4.0 SP2 (KB936181)
                                        MSXML 4.0 SP2 (KB941833)
                                        NTI Backup NOW! 4.7
                                        NTI Backup NOW! 4.7
                                        NTI CD & DVD-Maker
                                        OpenOffice.org Installer 1.0
                                        PowerProducer 3.72
                                        QuickTime
                                        Realtek High Definition Audio Driver
                                        Rhapsody Player Engine
                                        SUPERAntiSpyware Professional
                                        Yahoo! Toolbar


                                        delgado

                                          Topic Starter


                                          Beginner

                                          Re: how to get rid antivirus 2009
                                          « Reply #26 on: September 23, 2008, 08:49:39 PM »
                                          when i did hijack scan the only file that showed up in the fix checked screen was         O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe    but the others still show up on the hijack log   

                                          evilfantasy

                                          • Malware Removal Specialist
                                          • Moderator


                                          • Genius
                                          • Calm like a bomb
                                          • Thanked: 493
                                          • Experience: Experienced
                                          • OS: Windows 11
                                          Re: how to get rid antivirus 2009
                                          « Reply #27 on: September 23, 2008, 08:51:07 PM »

                                          Press the Start/windows key, type msconfig and hit Enter. Under the Boot tab, uncheck Safe boot as a boot option.

                                          Restart the computer and see if you can get into Normal mode.

                                          evilfantasy

                                          • Malware Removal Specialist
                                          • Moderator


                                          • Genius
                                          • Calm like a bomb
                                          • Thanked: 493
                                          • Experience: Experienced
                                          • OS: Windows 11
                                          Re: how to get rid antivirus 2009
                                          « Reply #28 on: September 23, 2008, 08:52:21 PM »
                                          Scan Suspicious File(s)

                                          Use the VirusTotal.com - Multi engine on-line virus scanner
                                          (If more than one file needs scanned they must be done separately and logs posted for each one)

                                          • Copy the file path in the below Code box:
                                          Code: [Select]
                                          C:\Windows\SUE81DD.exe
                                          • At the upload site, click once inside the window next to Browse.
                                          • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
                                          • Next click Send File
                                            • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
                                          • This will perform a scan across multiple different virus scanning engines.
                                          • Important: Wait for all of the scanning engines to complete.
                                          • Copy and then Paste the link to the results in the next reply.

                                          delgado

                                            Topic Starter


                                            Beginner

                                            Re: how to get rid antivirus 2009
                                            « Reply #29 on: September 23, 2008, 09:29:54 PM »
                                            0 bytes size received / Se ha recibido un archivo vacio
                                            here's the virus scan results also did another hijack scan ,still in safe mode

                                            delgado

                                              Topic Starter


                                              Beginner

                                              Re: how to get rid antivirus 2009
                                              « Reply #30 on: September 23, 2008, 09:33:57 PM »
                                              Logfile of Trend Micro HijackThis v2.0.2
                                              Scan saved at 12:36:44 PM, on 9/21/2008
                                              Platform: Windows Vista  (WinNT 6.00.1904)
                                              MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                                              Boot mode: Safe mode with network support

                                              Running processes:
                                              C:\Windows\System32\smss.exe
                                              C:\Windows\system32\csrss.exe
                                              C:\Windows\system32\csrss.exe
                                              C:\Windows\system32\wininit.exe
                                              C:\Windows\system32\winlogon.exe
                                              C:\Windows\system32\services.exe
                                              C:\Windows\system32\lsass.exe
                                              C:\Windows\system32\lsm.exe
                                              C:\Windows\system32\svchost.exe
                                              C:\Windows\system32\svchost.exe
                                              C:\Windows\System32\svchost.exe
                                              C:\Windows\System32\svchost.exe
                                              C:\Windows\system32\svchost.exe
                                              C:\Windows\System32\svchost.exe
                                              C:\Windows\system32\svchost.exe
                                              C:\Windows\system32\svchost.exe
                                              C:\Windows\system32\svchost.exe
                                              C:\Windows\Explorer.EXE
                                              C:\Windows\system32\svchost.exe
                                              C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                              C:\Program Files\Spyware Doctor\pctsSvc.exe
                                              C:\Program Files\Spyware Doctor\pctsTray.exe
                                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                                              C:\Program Files\Internet Explorer\iexplore.exe
                                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                              C:\Windows\system32\wbem\wmiprvse.exe

                                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
                                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
                                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                              O1 - Hosts: ::1 localhost
                                              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                              O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
                                              O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                              O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                                              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                              O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                              O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                              O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                                              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                              O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
                                              O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
                                              O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                              O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                              O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
                                              O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
                                              O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe
                                              O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                                              O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                              O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                              O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                              O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                              O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                              O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
                                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                              O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
                                              O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                              O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                              O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                              O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                              O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                              O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                              O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                                              O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000
                                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                              O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\logan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
                                              O13 - Gopher Prefix:
                                              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                              O20 - AppInit_DLLs: eNetHook.dll,avgrsstx.dll
                                              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                              O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                                              O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                                              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                              O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                              O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                              O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                              O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                                              O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                                              O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                                              O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                              O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                                              O23 - Service: Fix-It Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
                                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                              O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
                                              O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                                              O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
                                              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                                              O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                                              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                              --
                                              End of file - 9815 bytes

                                              evilfantasy

                                              • Malware Removal Specialist
                                              • Moderator


                                              • Genius
                                              • Calm like a bomb
                                              • Thanked: 493
                                              • Experience: Experienced
                                              • OS: Windows 11
                                              Re: how to get rid antivirus 2009
                                              « Reply #31 on: September 23, 2008, 09:37:26 PM »
                                              Go to C:\Program Files\Spyware Doctor and see if you can find an uninstaller in there and uninstall Spyware Doctor. I don't see it listed in the uninstall list.

                                              ----------

                                              Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

                                              http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                              Delete these files/folders, as follows:

                                              1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
                                              It must be Notepad, not Wordpad.
                                              2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

                                              Code: [Select]
                                              KillAll::

                                              File::
                                              C:\Windows\SUE73BA.exe
                                              C:\Windows\SUE7CBF.exe
                                              C:\Windows\SUE81DD.exe
                                              C:\Windows\SUE85D3.exe
                                              C:\Windows\SUE978F.exe
                                              C:\Windows\SUE73BA.exe
                                              C:\Windows\SUE7CBF.exe
                                              C:\Windows\SUE81DD.exe
                                              C:\Windows\SUE85D3.exe
                                              C:\Windows\SUE978F.exe

                                              3. Go to the Notepad window and click Edit > Paste
                                              4. Then click File > Save
                                              5. Name the file CFScript.txt - Save the file to your Desktop
                                              6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



                                              ComboFix will begin to execute, just follow the prompts.
                                              After reboot (in case it asks to reboot), it will produce a log for you.
                                              Post that log (Combofix.txt) in your next reply.

                                              Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

                                              ----------

                                              Do you have your Vista install CD?

                                              delgado

                                                Topic Starter


                                                Beginner

                                                Re: how to get rid antivirus 2009
                                                « Reply #32 on: September 23, 2008, 10:08:23 PM »
                                                didnt see spydoctor but found morpheus toolbar hiding in there and deleted it downloading combofix now

                                                delgado

                                                  Topic Starter


                                                  Beginner

                                                  Re: how to get rid antivirus 2009
                                                  « Reply #33 on: September 23, 2008, 11:04:08 PM »
                                                  ComboFix 08-09-22.06 - logan 2008-09-24  0:34:00.1 - NTFSx86
                                                  Microsoft® Windows Vista™ Home Basic   6.0.6000.0.1252.1.1033.18.379 [GMT -4:00]
                                                  Running from: C:\Users\logan\Downloads\ComboFix.exe
                                                  Command switches used :: C:\Users\logan\Desktop\CFScript.txt
                                                   * Created a new restore point

                                                  FILE ::
                                                  C:\Windows\SUE73BA.exe
                                                  C:\Windows\SUE7CBF.exe
                                                  C:\Windows\SUE81DD.exe
                                                  C:\Windows\SUE85D3.exe
                                                  C:\Windows\SUE978F.exe
                                                  .

                                                  (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
                                                  .

                                                  C:\Users\logan\AppData\Local\cageaew_navup.dat
                                                  C:\Windows\system32\x64

                                                  .
                                                  (((((((((((((((((((((((((   Files Created from 2008-08-24 to 2008-09-24  )))))))))))))))))))))))))))))))
                                                  .

                                                  2008-09-23 11:16 . 2007-02-21 19:56   49,904   --a------   C:\Windows\System32\drivers\BVRPMPR5.SYS
                                                  2008-09-22 15:11 . 2008-09-22 15:11   <DIR>   d--------   C:\Users\All Users\NortonInstaller
                                                  2008-09-22 15:11 . 2008-09-22 15:11   <DIR>   d--------   C:\ProgramData\NortonInstaller
                                                  2008-09-22 10:19 . 2008-09-22 12:43   <DIR>   d--------   C:\Users\logan\DoctorWeb
                                                  2008-09-21 19:45 . 2008-09-21 19:45   <DIR>   d--------   C:\Program Files\Sun
                                                  2008-09-21 15:36 . 2008-09-21 15:36   <DIR>   d--------   C:\Program Files\Trend Micro
                                                  2008-09-21 15:32 . 2008-09-21 15:32   <DIR>   d--------   C:\Windows\Sun
                                                  2008-09-21 12:46 . 2008-09-23 14:27   <DIR>   d--------   C:\Windows\System32\drivers\Avg
                                                  2008-09-21 12:46 . 2008-09-21 12:46   97,928   --a------   C:\Windows\System32\drivers\avgldx86.sys
                                                  2008-09-21 12:46 . 2008-09-21 12:46   69,128   --a------   C:\Windows\System32\drivers\avgwfpx.sys
                                                  2008-09-21 12:46 . 2008-09-21 12:46   10,520   --a------   C:\Windows\System32\avgrsstx.dll
                                                  2008-09-21 12:36 . 2008-09-21 12:36   <DIR>   d--------   C:\Users\All Users\SUPERAntiSpyware.com
                                                  2008-09-21 12:36 . 2008-09-21 12:36   <DIR>   d--------   C:\ProgramData\SUPERAntiSpyware.com
                                                  2008-09-21 12:35 . 2008-09-21 12:35   <DIR>   d--------   C:\Users\logan\AppData\Roaming\SUPERAntiSpyware.com
                                                  2008-09-21 12:35 . 2008-09-21 12:35   <DIR>   d--------   C:\Program Files\SUPERAntiSpyware
                                                  2008-09-21 12:16 . 2008-09-21 12:16   <DIR>   d--------   C:\Program Files\CCleaner
                                                  2008-09-09 15:59 . 2008-07-30 19:47   4,247,552   --a------   C:\Windows\System32\GameUXLegacyGDFs.dll
                                                  2008-09-09 15:59 . 2008-07-30 23:34   1,686,528   --a------   C:\Windows\System32\gameux.dll
                                                  2008-09-09 15:59 . 2008-07-30 23:34   28,160   --a------   C:\Windows\System32\Apphlpdm.dll
                                                  2008-09-09 15:58 . 2008-06-25 23:22   303,616   --a------   C:\Windows\System32\wmpeffects.dll
                                                  2008-08-28 02:37 . 2007-09-02 23:56   1,686,016   --a------   C:\Windows\System32\clinetsuitex6.ocx
                                                  2008-08-28 02:37 . 2004-06-14 17:56   427,864   --a------   C:\Windows\System32\XceedZip.dll
                                                  2008-08-27 21:51 . 2004-03-09 19:45   662,288   --a------   C:\Windows\System32\MSCOMCT2.OCX
                                                  2008-08-26 17:14 . 2008-08-26 17:14   19,200   --a------   C:\Windows\System32\drivers\mxRCycle.sys

                                                  .
                                                  ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
                                                  .
                                                  2008-09-23 18:26   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
                                                  2008-09-23 18:26   ---------   d-----w   C:\ProgramData\BVRP Software
                                                  2008-09-22 19:12   ---------   d-----w   C:\Program Files\Common Files\Symantec Shared
                                                  2008-09-22 02:58   ---------   d---a-w   C:\ProgramData\TEMP
                                                  2008-09-21 23:43   ---------   d-----w   C:\Program Files\Java
                                                  2008-09-21 19:09   ---------   d-----w   C:\Program Files\Malwarebytes' Anti-Malware
                                                  2008-09-21 16:45   ---------   d-----w   C:\ProgramData\avg8
                                                  2008-09-21 16:33   ---------   d-----w   C:\Program Files\Common Files\Wise Installation Wizard
                                                  2008-09-21 16:09   ---------   d-----w   C:\ProgramData\Viewpoint
                                                  2008-09-10 07:04   38,528   ----a-w   C:\Windows\system32\drivers\mbamswissarmy.sys
                                                  2008-09-10 07:03   17,200   ----a-w   C:\Windows\system32\drivers\mbam.sys
                                                  2008-08-22 18:00   29,600   ----a-w   C:\Windows\System32\mxntdfg.exe
                                                  2008-08-14 16:21   ---------   d-----w   C:\Program Files\Windows Mail
                                                  2008-08-09 05:37   ---------   d-----w   C:\Users\logan\AppData\Roaming\MySpace
                                                  2008-08-02 03:57   ---------   d-----w   C:\Program Files\Microsoft Windows OneCare Live
                                                  2008-07-31 03:34   537,600   ----a-w   C:\Windows\AppPatch\AcLayers.dll
                                                  2008-07-31 03:34   449,536   ----a-w   C:\Windows\AppPatch\AcSpecfc.dll
                                                  2008-07-31 03:34   2,144,256   ----a-w   C:\Windows\AppPatch\AcGenral.dll
                                                  2008-07-31 03:34   173,056   ----a-w   C:\Windows\AppPatch\AcXtrnal.dll
                                                  2008-07-31 02:41   ---------   d-----w   C:\Program Files\Google
                                                  2008-07-30 23:32   2,560   ----a-w   C:\Windows\AppPatch\AcRes.dll
                                                  2008-07-30 19:05   ---------   d-----w   C:\Users\logan\AppData\Roaming\Malwarebytes
                                                  2008-07-30 19:04   ---------   d-----w   C:\ProgramData\Malwarebytes
                                                  2008-07-30 16:36   ---------   d-----w   C:\Users\logan\AppData\Roaming\Download Manager
                                                  2008-07-30 06:16   ---------   d-----w   C:\Program Files\Enigma Software Group
                                                  2008-07-30 00:11   ---------   d-----w   C:\Users\logan\AppData\Roaming\Avanquest
                                                  2008-07-30 00:11   ---------   d-----w   C:\ProgramData\Avanquest
                                                  2008-07-30 00:09   ---------   d-----w   C:\ProgramData\CyberLink
                                                  2008-07-30 00:01   ---------   d-----w   C:\ProgramData\Spybot - Search & Destroy
                                                  2008-07-29 20:21   ---------   d-----w   C:\Program Files\Avanquest
                                                  2008-07-29 03:33   ---------   d-----w   C:\Program Files\Acer GameZone
                                                  2008-07-19 05:10   53,448   ----a-w   C:\Windows\System32\wuauclt.exe
                                                  2008-07-19 05:10   45,768   ----a-w   C:\Windows\System32\wups2.dll
                                                  2008-07-19 05:10   36,552   ----a-w   C:\Windows\System32\wups.dll
                                                  2008-07-19 05:09   563,912   ----a-w   C:\Windows\System32\wuapi.dll
                                                  2008-07-19 05:09   1,811,656   ----a-w   C:\Windows\System32\wuaueng.dll
                                                  2008-07-19 05:08   163,904   ----a-w   C:\Windows\System32\wuwebv.dll
                                                  2008-07-19 03:44   83,456   ----a-w   C:\Windows\System32\wudriver.dll
                                                  2008-07-19 03:44   31,232   ----a-w   C:\Windows\System32\wuapp.exe
                                                  2008-07-19 03:44   1,524,736   ----a-w   C:\Windows\System32\wucltux.dll
                                                  2008-07-15 23:48   2,048   ----a-w   C:\Windows\System32\tzres.dll
                                                  2008-07-10 17:13   174   --sha-w   C:\Program Files\desktop.ini
                                                  2008-06-27 03:54   826,368   ----a-w   C:\Windows\System32\wininet.dll
                                                  2008-06-27 03:54   56,320   ----a-w   C:\Windows\System32\iesetup.dll
                                                  2008-06-27 03:54   52,736   ----a-w   C:\Windows\AppPatch\iebrshim.dll
                                                  2008-06-27 03:54   26,624   ----a-w   C:\Windows\System32\ieUnatt.exe
                                                  2008-06-26 00:34   7,964,672   ----a-w   C:\Windows\System32\NlsLexicons0024.dll
                                                  2008-06-26 00:33   9,892,864   ----a-w   C:\Windows\System32\NlsLexicons000a.dll
                                                  .

                                                  (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
                                                  .
                                                  .
                                                  *Note* empty entries & legit default entries are not shown
                                                  REGEDIT4

                                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                                  "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 1232896]
                                                  "EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
                                                  "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-07-30 171448]
                                                  "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]

                                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                                  "eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
                                                  "LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-07-16 768520]
                                                  "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2007-06-06 159744]
                                                  "Acer Product Registration"="C:\Program Files\Acer Registration\ACE1.exe" [2007-02-02 3383296]
                                                  "Acer Assist Launcher"="C:\Program Files\Acer Assist\launcher.exe" [2007-02-02 1261568]
                                                  "Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-05-22 151552]
                                                  "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 286720]
                                                  "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-01-02 141848]
                                                  "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-01-02 166424]
                                                  "Persistence"="C:\Windows\system32\igfxpers.exe" [2008-01-02 133656]
                                                  "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
                                                  "VirusScannerPro"="C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe" [2008-08-26 173312]
                                                  "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-21 1235736]
                                                  "Malwarebytes Anti-Malware (reboot)"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2008-09-10 1253040]
                                                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                                                  "MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 222208]
                                                  "RtHDVCpl"="RtHDVCpl.exe" [2007-07-05 C:\Windows\RtHDVCpl.exe]

                                                  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
                                                  Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-09-03 535336]

                                                  [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                                                  "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

                                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
                                                  2008-07-23 19:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

                                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                                  "AppInit_DLLs"=avgrsstx.dll eNetHook.dll

                                                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                                                  @="Driver"

                                                  [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                                  "UacDisableNotify"=dword:00000001
                                                  "InternetSettingsDisableNotify"=dword:00000001
                                                  "AutoUpdateDisableNotify"=dword:00000001

                                                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                                                  "DisableMonitoring"=dword:00000001

                                                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                                                  "DisableMonitoring"=dword:00000001

                                                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                                  "DisableMonitoring"=dword:00000001

                                                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
                                                  "DoNotAllowExceptions"= 0 (0x0)

                                                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                                                  "{35E1504D-0C3D-4D91-A511-B7B221F76B97}"= UDP:C:\Program Files\FrostWire\FrostWire.exe:FrostWire 4.13.4
                                                  "{DC800F1B-8AA6-44D8-86A9-53ECB87BA070}"= TCP:C:\Program Files\FrostWire\FrostWire.exe:FrostWire 4.13.4
                                                  "{53D05FE2-1A08-4A0F-857E-C9683D4E147C}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
                                                  "{D443ADAE-32CC-49FE-8956-ABD796E68EF0}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
                                                  "{5B4EE116-1030-43EE-BF46-A6D02A97AB5E}"= UDP:C:\Program Files\Morpheus\Morpheus.exe:Morpheus
                                                  "{FCA82B38-FD2D-4107-B1AF-A54572EADA40}"= TCP:C:\Program Files\Morpheus\Morpheus.exe:Morpheus
                                                  "{D36AFAE5-E0E9-4F2B-9902-BE77772F9C2C}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
                                                  "{142BBA8E-8FC0-4B8B-B228-C1C705B8FEA6}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe
                                                  "{C8F9504C-48AB-4FC2-A43D-11DBF4205506}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
                                                  "{8A520869-B294-42F2-BF00-E08DDE3B45F7}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
                                                  "{7DFCFC22-520E-483C-B22B-F72E58FEA2E8}"= UDP:C:\Program Files\AIM6\aim6.exe:AIM
                                                  "{102650FA-50AC-46CF-B01F-D296F08B5A1B}"= TCP:C:\Program Files\AIM6\aim6.exe:AIM
                                                  "TCP Query User{D05D548F-3880-49B2-A709-A41373E47C35}C:\\program files\\frostwire\\frostwire.exe"= UDP:C:\program files\frostwire\frostwire.exe:FrostWire
                                                  "UDP Query User{023572A0-541D-40C9-9451-38C553260CB4}C:\\program files\\frostwire\\frostwire.exe"= TCP:C:\program files\frostwire\frostwire.exe:FrostWire
                                                  "TCP Query User{7B5B36E2-C1AE-465F-BEC9-BDC01F763295}C:\\program files\\avanquest\\fix-it\\fix-it.exe"= UDP:C:\program files\avanquest\fix-it\fix-it.exe:Fix-It Utilities 8 Professional
                                                  "UDP Query User{4F07F327-ACBA-430F-ADB5-089D929AE211}C:\\program files\\avanquest\\fix-it\\fix-it.exe"= TCP:C:\program files\avanquest\fix-it\fix-it.exe:Fix-It Utilities 8 Professional

                                                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                                                  "DoNotAllowExceptions"= 0 (0x0)

                                                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
                                                  "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

                                                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                                                  "DoNotAllowExceptions"= 0 (0x0)

                                                  R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-09-21 97928]
                                                  R3 AvgWfpX;AVG Free8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-09-21 69128]
                                                  R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-06-05 179712]

                                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                                                  LocalServiceNoNetwork   REG_MULTI_SZ      PLA DPS BFE mpssvc
                                                  bthsvcs   REG_MULTI_SZ      BthServ
                                                  .
                                                  - - - - ORPHANS REMOVED - - - -

                                                  WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
                                                  WebBrowser-{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - (no file)
                                                  HKCU-Run-Acer Tour Reminder - (no file)



                                                  **************************************************************************

                                                  catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                                  Rootkit scan 2008-09-24 00:42:20
                                                  Windows 6.0.6000  NTFS

                                                  scanning hidden processes ...

                                                  scanning hidden autostart entries ...

                                                  scanning hidden files ...

                                                  scan completed successfully
                                                  hidden files: 0

                                                  **************************************************************************
                                                  .
                                                  ------------------------ Other Running Processes ------------------------
                                                  .
                                                  C:\Windows\System32\audiodg.exe
                                                  C:\Windows\System32\agrsmsvc.exe
                                                  C:\Acer\ALaunch\ALaunchSvc.exe
                                                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                                  C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                                                  C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                                                  C:\Acer\Empowering Technology\eNet\eNet Service.exe
                                                  C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
                                                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                                  C:\Program Files\Common Files\Motive\McciCMService.exe
                                                  C:\Acer\Mobility Center\MobilityService.exe
                                                  C:\Windows\System32\drivers\XAudio.exe
                                                  C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                                  C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                                                  C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                                                  C:\Windows\System32\wbem\unsecapp.exe
                                                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                                                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                                  C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
                                                  C:\Program Files\Launch Manager\LManager.exe
                                                  C:\Program Files\AVG\AVG8\avgtray.exe
                                                  C:\Windows\System32\igfxsrvc.exe
                                                  C:\Users\logan\AppData\Local\Temp\RtkBtMnt.exe
                                                  C:\Windows\System32\igfxext.exe
                                                  C:\Windows\System32\igfxsrvc.exe
                                                  C:\Acer\Empowering Technology\eNet\eNMTray.exe
                                                  C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
                                                  C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
                                                  C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                                                  C:\Program Files\Apoint2K\ApMsgFwd.exe
                                                  C:\Program Files\Apoint2K\ApntEx.exe
                                                  C:\Windows\System32\lpremove.exe
                                                  C:\Windows\System32\lpksetup.exe
                                                  C:\Windows\servicing\TrustedInstaller.exe
                                                  .
                                                  **************************************************************************
                                                  .
                                                  Completion time: 2008-09-24  0:59:58 - machine was rebooted [logan]
                                                  ComboFix-quarantined-files.txt  2008-09-24 04:58:48

                                                  Pre-Run: 459,603,968 bytes free
                                                  Post-Run: 59,523,072 bytes free

                                                  234   --- E O F ---   2008-09-18 20:50:07

                                                  delgado

                                                    Topic Starter


                                                    Beginner

                                                    Re: how to get rid antivirus 2009
                                                    « Reply #34 on: September 23, 2008, 11:12:37 PM »
                                                    Thanks for being patient with me here's a new hjt scan                  Logfile of Trend Micro HijackThis v2.0.2
                                                    Scan saved at 12:36:44 PM, on 9/21/2008
                                                    Platform: Windows Vista  (WinNT 6.00.1904)
                                                    MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                                                    Boot mode: Safe mode with network support

                                                    Running processes:
                                                    C:\Windows\System32\smss.exe
                                                    C:\Windows\system32\csrss.exe
                                                    C:\Windows\system32\csrss.exe
                                                    C:\Windows\system32\wininit.exe
                                                    C:\Windows\system32\winlogon.exe
                                                    C:\Windows\system32\services.exe
                                                    C:\Windows\system32\lsass.exe
                                                    C:\Windows\system32\lsm.exe
                                                    C:\Windows\system32\svchost.exe
                                                    C:\Windows\system32\svchost.exe
                                                    C:\Windows\System32\svchost.exe
                                                    C:\Windows\System32\svchost.exe
                                                    C:\Windows\system32\svchost.exe
                                                    C:\Windows\System32\svchost.exe
                                                    C:\Windows\system32\svchost.exe
                                                    C:\Windows\system32\svchost.exe
                                                    C:\Windows\system32\svchost.exe
                                                    C:\Windows\Explorer.EXE
                                                    C:\Windows\system32\svchost.exe
                                                    C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                                    C:\Program Files\Spyware Doctor\pctsSvc.exe
                                                    C:\Program Files\Spyware Doctor\pctsTray.exe
                                                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                                                    C:\Program Files\Internet Explorer\iexplore.exe
                                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                                    C:\Windows\system32\wbem\wmiprvse.exe

                                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
                                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                                    O1 - Hosts: ::1 localhost
                                                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                                    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
                                                    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                                    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                                                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                                    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                                    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                                    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                                                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                                    O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
                                                    O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
                                                    O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                                    O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                                    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                                    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                                    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                                    O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
                                                    O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
                                                    O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe
                                                    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                                                    O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                                    O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                                    O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                                    O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                                    O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                                    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                                    O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
                                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                                    O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
                                                    O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                                    O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                                    O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                                    O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                                    O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                                    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                                    O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                                                    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000
                                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                                    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\logan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
                                                    O13 - Gopher Prefix:
                                                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                                    O20 - AppInit_DLLs: eNetHook.dll,avgrsstx.dll
                                                    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                                    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                                                    O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                                                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                                    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                                    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                                    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                                    O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                                                    O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                                                    O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                                                    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                                    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                                                    O23 - Service: Fix-It Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
                                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                                    O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
                                                    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                                                    O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
                                                    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                                    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                                                    O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                                                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                                    --
                                                    End of file - 9815 bytes

                                                    evilfantasy

                                                    • Malware Removal Specialist
                                                    • Moderator


                                                    • Genius
                                                    • Calm like a bomb
                                                    • Thanked: 493
                                                    • Experience: Experienced
                                                    • OS: Windows 11
                                                    Re: how to get rid antivirus 2009
                                                    « Reply #35 on: September 23, 2008, 11:17:21 PM »
                                                    Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

                                                    Go to Start > Run and type notepad.exe then click OK

                                                    Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

                                                    Code: [Select]
                                                    REGEDIT4

                                                    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

                                                    Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

                                                    Make sure that you tell me if you receive a success message about adding the above
                                                    to the registry. If you do not get a success message, it did not work.


                                                    Delete the fixme.reg from the Desktop.

                                                    Try to boot into Normal mode.

                                                    evilfantasy

                                                    • Malware Removal Specialist
                                                    • Moderator


                                                    • Genius
                                                    • Calm like a bomb
                                                    • Thanked: 493
                                                    • Experience: Experienced
                                                    • OS: Windows 11
                                                    Re: how to get rid antivirus 2009
                                                    « Reply #36 on: September 23, 2008, 11:18:40 PM »
                                                    Do you have your Vista install disk?

                                                    delgado

                                                      Topic Starter


                                                      Beginner

                                                      Re: how to get rid antivirus 2009
                                                      « Reply #37 on: September 23, 2008, 11:23:09 PM »
                                                      yes gotta find it right quick

                                                      delgado

                                                        Topic Starter


                                                        Beginner

                                                        Re: how to get rid antivirus 2009
                                                        « Reply #38 on: September 23, 2008, 11:26:41 PM »
                                                        k got it what's next?

                                                        evilfantasy

                                                        • Malware Removal Specialist
                                                        • Moderator


                                                        • Genius
                                                        • Calm like a bomb
                                                        • Thanked: 493
                                                        • Experience: Experienced
                                                        • OS: Windows 11
                                                        Re: how to get rid antivirus 2009
                                                        « Reply #39 on: September 23, 2008, 11:42:21 PM »
                                                        Follow this guide. It isn't a reinstall it is only a repair.

                                                        How To Perform a Repair Installation For Vista

                                                        delgado

                                                          Topic Starter


                                                          Beginner

                                                          Re: how to get rid antivirus 2009
                                                          « Reply #40 on: September 23, 2008, 11:58:43 PM »
                                                          put disc in nothing happens

                                                          delgado

                                                            Topic Starter


                                                            Beginner

                                                            Re: how to get rid antivirus 2009
                                                            « Reply #41 on: September 24, 2008, 12:11:06 AM »
                                                            missed the     ( REGEDIT4

                                                            [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] )     registry merge , just ran it and it was a success

                                                            evilfantasy

                                                            • Malware Removal Specialist
                                                            • Moderator


                                                            • Genius
                                                            • Calm like a bomb
                                                            • Thanked: 493
                                                            • Experience: Experienced
                                                            • OS: Windows 11
                                                            Re: how to get rid antivirus 2009
                                                            « Reply #42 on: September 24, 2008, 12:13:11 AM »
                                                            Can you boot into Normal mode now?

                                                            I have asked someone else to help with advise on the repair install. It might take them a bit to get to this thread but shouldn't be too long.

                                                            evilfantasy

                                                            • Malware Removal Specialist
                                                            • Moderator


                                                            • Genius
                                                            • Calm like a bomb
                                                            • Thanked: 493
                                                            • Experience: Experienced
                                                            • OS: Windows 11
                                                            Re: how to get rid antivirus 2009
                                                            « Reply #43 on: September 24, 2008, 01:02:48 AM »
                                                            Also try this.

                                                            Press the Start/windows key, type msconfig and hit Enter. Under the Boot tab, uncheck Safe boot as a boot option.

                                                            Restart the computer and see if you can get into Normal mode.

                                                            delgado

                                                              Topic Starter


                                                              Beginner

                                                              Re: how to get rid antivirus 2009
                                                              « Reply #44 on: September 24, 2008, 05:17:21 AM »
                                                              safe boot is not checked here

                                                              evilfantasy

                                                              • Malware Removal Specialist
                                                              • Moderator


                                                              • Genius
                                                              • Calm like a bomb
                                                              • Thanked: 493
                                                              • Experience: Experienced
                                                              • OS: Windows 11
                                                              Re: how to get rid antivirus 2009
                                                              « Reply #45 on: September 24, 2008, 10:30:42 AM »
                                                              When you put the CD in if it does not start automatically you need to go into Computer or My Computer from the Desktop and start the CD that way.

                                                              delgado

                                                                Topic Starter


                                                                Beginner

                                                                Re: how to get rid antivirus 2009
                                                                « Reply #46 on: September 24, 2008, 12:14:31 PM »
                                                                pulled it the disc up on my computer but dont know where to go from here ???

                                                                evilfantasy

                                                                • Malware Removal Specialist
                                                                • Moderator


                                                                • Genius
                                                                • Calm like a bomb
                                                                • Thanked: 493
                                                                • Experience: Experienced
                                                                • OS: Windows 11
                                                                Re: how to get rid antivirus 2009
                                                                « Reply #47 on: September 24, 2008, 12:30:21 PM »
                                                                I found another repair option to look at.
                                                                http://www.bleepingcomputer.com/tutorials/tutorial148.html

                                                                delgado

                                                                  Topic Starter


                                                                  Beginner

                                                                  Re: how to get rid antivirus 2009
                                                                  « Reply #48 on: September 24, 2008, 01:21:51 PM »
                                                                  went to this link but my disc does not have repair option showing should i click install now ?or how do i boot from disc ?

                                                                  evilfantasy

                                                                  • Malware Removal Specialist
                                                                  • Moderator


                                                                  • Genius
                                                                  • Calm like a bomb
                                                                  • Thanked: 493
                                                                  • Experience: Experienced
                                                                  • OS: Windows 11
                                                                  Re: how to get rid antivirus 2009
                                                                  « Reply #49 on: September 24, 2008, 01:28:20 PM »
                                                                  I am really not sure... Not a Vista user ???

                                                                  delgado

                                                                    Topic Starter


                                                                    Beginner

                                                                    Re: how to get rid antivirus 2009
                                                                    « Reply #50 on: September 24, 2008, 04:06:41 PM »
                                                                    thanks for all the help computer seems to be booting on normal mode but stiill says safe boot on hjt log but when i do boot manually in safe mode has a whole different look than now?

                                                                    evilfantasy

                                                                    • Malware Removal Specialist
                                                                    • Moderator


                                                                    • Genius
                                                                    • Calm like a bomb
                                                                    • Thanked: 493
                                                                    • Experience: Experienced
                                                                    • OS: Windows 11
                                                                    Re: how to get rid antivirus 2009
                                                                    « Reply #51 on: September 24, 2008, 04:07:34 PM »
                                                                    Post a fresh HJT log please.

                                                                    delgado

                                                                      Topic Starter


                                                                      Beginner

                                                                      Re: how to get rid antivirus 2009
                                                                      « Reply #52 on: September 25, 2008, 06:14:08 AM »
                                                                      Logfile of Trend Micro HijackThis v2.0.2
                                                                      Scan saved at 12:36:44 PM, on 9/21/2008
                                                                      Platform: Windows Vista  (WinNT 6.00.1904)
                                                                      MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                                                                      Boot mode: Safe mode with network support

                                                                      Running processes:
                                                                      C:\Windows\System32\smss.exe
                                                                      C:\Windows\system32\csrss.exe
                                                                      C:\Windows\system32\csrss.exe
                                                                      C:\Windows\system32\wininit.exe
                                                                      C:\Windows\system32\winlogon.exe
                                                                      C:\Windows\system32\services.exe
                                                                      C:\Windows\system32\lsass.exe
                                                                      C:\Windows\system32\lsm.exe
                                                                      C:\Windows\system32\svchost.exe
                                                                      C:\Windows\system32\svchost.exe
                                                                      C:\Windows\System32\svchost.exe
                                                                      C:\Windows\System32\svchost.exe
                                                                      C:\Windows\system32\svchost.exe
                                                                      C:\Windows\System32\svchost.exe
                                                                      C:\Windows\system32\svchost.exe
                                                                      C:\Windows\system32\svchost.exe
                                                                      C:\Windows\system32\svchost.exe
                                                                      C:\Windows\Explorer.EXE
                                                                      C:\Windows\system32\svchost.exe
                                                                      C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                                                      C:\Program Files\Spyware Doctor\pctsSvc.exe
                                                                      C:\Program Files\Spyware Doctor\pctsTray.exe
                                                                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                                                                      C:\Program Files\Internet Explorer\iexplore.exe
                                                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                                                      C:\Windows\system32\wbem\wmiprvse.exe

                                                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
                                                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
                                                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                                                      O1 - Hosts: ::1 localhost
                                                                      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                                      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                                                      O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
                                                                      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                                                      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                                                                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                                                      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                                                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                                                      O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                                                      O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                                                                      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                                                      O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
                                                                      O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
                                                                      O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                                                      O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                                                                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                                                      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                                                      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                                                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                                                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                                                      O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
                                                                      O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
                                                                      O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe
                                                                      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                                                                      O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                                                      O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                                                      O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                                                      O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                                                      O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                                                      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                                                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                                                      O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
                                                                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                                                      O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
                                                                      O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
                                                                      O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
                                                                      O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
                                                                      O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
                                                                      O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
                                                                      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                                                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                                                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                                                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                                                      O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                                                                      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000
                                                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                                                      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                                                      O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\logan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
                                                                      O13 - Gopher Prefix:
                                                                      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                                                      O20 - AppInit_DLLs: eNetHook.dll,avgrsstx.dll
                                                                      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                                                      O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                                                                      O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                                                                      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                                      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                                                      O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                                                      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                                                      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                                                      O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                                                                      O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                                                                      O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                                                                      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                                                      O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                                                                      O23 - Service: Fix-It Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
                                                                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                                                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                                                      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                                                      O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
                                                                      O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                                                                      O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
                                                                      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                                                      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                                                                      O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                                                                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                                                      --
                                                                      End of file - 9815 bytes

                                                                      delgado

                                                                        Topic Starter


                                                                        Beginner

                                                                        Re: how to get rid antivirus 2009
                                                                        « Reply #53 on: September 25, 2008, 06:29:46 AM »
                                                                        performance has gotten alot better,but still some issues

                                                                        evilfantasy

                                                                        • Malware Removal Specialist
                                                                        • Moderator


                                                                        • Genius
                                                                        • Calm like a bomb
                                                                        • Thanked: 493
                                                                        • Experience: Experienced
                                                                        • OS: Windows 11
                                                                        Re: how to get rid antivirus 2009
                                                                        « Reply #54 on: September 25, 2008, 09:10:24 AM »
                                                                        Run this online scan. Requires Internet Explorer

                                                                        Use the ESET Nod32 Online Scanner

                                                                        1. Check the box next to YES, I accept the Terms of Use.
                                                                        2. Click Start
                                                                        3. When asked, allow the activex control to install
                                                                        4. Click Start
                                                                        5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
                                                                        6. Click Scan
                                                                        7. Wait for the scan to finish
                                                                        8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
                                                                        9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.

                                                                        delgado

                                                                          Topic Starter


                                                                          Beginner

                                                                          Re: how to get rid antivirus 2009
                                                                          « Reply #55 on: September 25, 2008, 11:59:44 PM »
                                                                          just cant get nod 32 to download,i'll keep trying